Vulnerability index

Browse CVEs

162 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5531

Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and cre…

Mitigation only
Fix from $1,600 2013-10-25
Adaptive Security Appliance Software HIGH 10.0
CVE-2013-5511

The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), …

Mitigation only
Fix from $1,950 2013-10-13
Video Surveillance Operations Manager MEDIUM 5.0
CVE-2013-3417

The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attacke…

Mitigation only
Fix from $1,600 2013-09-30
Unified Computing System HIGH 8.5
CVE-2012-4078

The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote …

Mitigation only
Fix from $1,950 2013-09-24
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.8
CVE-2013-3473

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of …

Fix: after 9.1
Fix from $1,950 2013-09-20
Secure Access Control Server HIGH 9.3
CVE-2013-3466EPSS 5%

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled,…

Fix: after 4.2.1.15.10
Fix from $1,950 2013-08-29
Video Surveillance Manager HIGH 9.0
CVE-2013-3430EPSS 8%

Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspe…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Video Surveillance Manager HIGH 7.8
CVE-2013-3431EPSS 9%

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attacker…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Nx Os MEDIUM 5.0
CVE-2013-1209

The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Ne…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.0
CVE-2013-1211

Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communica…

Mitigation only
Fix from $1,600 2013-05-29
Secure Access Control System MEDIUM 6.8
CVE-2013-1200

Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, ak…

Mitigation only
Fix from $1,600 2013-05-16
Unified Communications Manager MEDIUM 5.0
CVE-2013-1188

Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2013-05-16
iOS MEDIUM 6.3
CVE-2013-1241

The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to caus…

Mitigation only
Fix from $1,600 2013-05-08
Unified Computing System Infrastructure And Unified Computing System Software HIGH 7.5
CVE-2013-1186

Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted auth…

Mitigation only
Fix from $1,950 2013-04-25
Adaptive Security Appliance Software HIGH 7.8
CVE-2013-1150

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31),…

Mitigation only
Fix from $1,950 2013-04-11
Firewall Services Module Software HIGH 7.8
CVE-2013-1155

The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1…

Mitigation only
Fix from $1,950 2013-04-11
Unified Communications Manager HIGH 7.1
CVE-2013-1134

The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not req…

Mitigation only
Fix from $1,950 2013-02-27
Adaptive Security Appliance Software HIGH 7.1
CVE-2012-4659

The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Modul…

Mitigation only
Fix from $1,950 2012-10-29
Intrusion Prevention System MEDIUM 5.0
CVE-2011-4022

The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and ma…

Mitigation only
Fix from $1,600 2012-05-03
Small Business Ip Phone Firmware MEDIUM 5.0
CVE-2012-0333

Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remot…

Fix: after 7.4.9
Fix from $1,600 2012-05-02
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2012-0335

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attemp…

Mitigation only
Fix from $1,600 2012-05-02
Adaptive Security Appliance Software HIGH 7.9
CVE-2011-3298

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…

Mitigation only
Fix from $1,950 2011-10-06
Firewall Services Module Software HIGH 7.8
CVE-2011-3297

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authenticat…

Mitigation only
Fix from $1,950 2011-10-06
Telepresence Recording Server Software HIGH 7.5
CVE-2011-0392

Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Recording Server Software HIGH 10.0
CVE-2011-0383EPSS 6%

The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Multipoint Switch Software HIGH 10.0
CVE-2011-0384EPSS 6%

The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require admin…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Manager HIGH 7.5
CVE-2011-0380

Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP req…

Mitigation only
Fix from $1,950 2011-02-25
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2010-4690

The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly …

Fix: after 8.3
Fix from $1,600 2011-01-07
Scientific Atlanta Webstar Dpc2100r2 MEDIUM 6.4
CVE-2010-2026

The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass aut…

No fix yet
Fix from $1,600 2010-05-26
iOS HIGH 7.1
CVE-2009-2863

Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypas…

Mitigation only
Fix from $1,950 2009-09-28